Vulnerabilities > CVE-2003-0109 - Unspecified vulnerability in Microsoft Windows 2000 and Windows 2000 Terminal Services

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
microsoft
nessus
exploit available
metasploit

Summary

Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.

Vulnerable Configurations

Part Description Count
OS
Microsoft
8

Exploit-Db

  • descriptionMicrosoft Windows XP/2000/NT 4 ntdll.dll Buffer Overflow Vulnerability (1). CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:22365
    last seen2016-02-02
    modified2003-03-24
    published2003-03-24
    reportermat
    sourcehttps://www.exploit-db.com/download/22365/
    titleMicrosoft Windows XP/2000/NT 4 ntdll.dll Buffer Overflow Vulnerability 1
  • descriptionMicrosoft Windows XP/2000/NT 4 ntdll.dll Buffer Overflow Vulnerability (3). CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:22367
    last seen2016-02-02
    modified2003-04-04
    published2003-04-04
    reporterMorning Wood
    sourcehttps://www.exploit-db.com/download/22367/
    titleMicrosoft Windows XP/2000/NT 4 ntdll.dll Buffer Overflow Vulnerability 3
  • descriptionMS Windows WebDAV (ntdll.dll) Remote Exploit. CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:1
    last seen2016-01-31
    modified2003-03-23
    published2003-03-23
    reporterkralor
    sourcehttps://www.exploit-db.com/download/1/
    titleMicrosoft Windows WebDAV - ntdll.dll Remote Exploit
  • descriptionMicrosoft IIS 5.0 WebDAV ntdll.dll Path Overflow. CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:16470
    last seen2016-02-01
    modified2010-07-25
    published2010-07-25
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16470/
    titleMicrosoft IIS 5.0 WebDAV ntdll.dll Path Overflow
  • descriptionMS Windows WebDav III remote root Exploit (xwdav). CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:51
    last seen2016-01-31
    modified2003-07-08
    published2003-07-08
    reporterSchizoprenic
    sourcehttps://www.exploit-db.com/download/51/
    titleMicrosoft Windows WebDav III - Remote Root Exploit xwdav
  • descriptionMS Windows WebDAV Remote PoC Exploit. CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:2
    last seen2016-01-31
    modified2003-03-24
    published2003-03-24
    reporterRoMaNSoFt
    sourcehttps://www.exploit-db.com/download/2/
    titleMicrosoft Windows WebDAV - Remote PoC Exploit
  • descriptionMS Windows WebDav II (New) Remote Root Exploit. CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:36
    last seen2016-01-31
    modified2003-06-01
    published2003-06-01
    reporteralumni
    sourcehttps://www.exploit-db.com/download/36/
    titleMicrosoft Windows WebDav II - Remote Root Exploit 2
  • descriptionMicrosoft Windows XP/2000/NT 4 ntdll.dll Buffer Overflow Vulnerability (2). CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:22366
    last seen2016-02-02
    modified2003-03-31
    published2003-03-31
    reporterThreaT
    sourcehttps://www.exploit-db.com/download/22366/
    titleMicrosoft Windows XP/2000/NT 4 ntdll.dll Buffer Overflow Vulnerability 2
  • descriptionMicrosoft Windows XP/2000/NT 4 ntdll.dll Buffer Overflow Vulnerability (4). CVE-2003-0109. Remote exploit for windows platform
    idEDB-ID:22368
    last seen2016-02-02
    modified2003-03-17
    published2003-03-17
    reporter[email protected]
    sourcehttps://www.exploit-db.com/download/22368/
    titleMicrosoft Windows XP/2000/NT 4 ntdll.dll Buffer Overflow Vulnerability 4

Metasploit

descriptionThis exploits a buffer overflow in NTDLL.dll on Windows 2000 through the SEARCH WebDAV method in IIS. This particular module only works against Windows 2000. It should have a reasonable chance of success against any service pack.
idMSF:EXPLOIT/WINDOWS/IIS/MS03_007_NTDLL_WEBDAV
last seen2020-01-10
modified2017-07-24
published2007-03-01
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0109
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/iis/ms03_007_ntdll_webdav.rb
titleMS03-007 Microsoft IIS 5.0 WebDAV ntdll.dll Path Overflow

Nessus

  • NASL familyWeb Servers
    NASL idIIS_WEBDAV_OVERFLOW.NASL
    descriptionThe remote WebDAV server is vulnerable to a buffer overflow when it receives a too long request. An attacker may use this flaw to execute arbitrary code within the LocalSystem security context.
    last seen2020-06-01
    modified2020-06-02
    plugin id11412
    published2003-03-18
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11412
    titleMicrosoft IIS WebDAV ntdll.dll Remote Overflow (MS03-007)
  • NASL familyWindows : Microsoft Bulletins
    NASL idSMB_NT_MS03-007.NASL
    descriptionThe remote version of Windows contains a buffer overflow in the Windows kernel, that could allow an attacker to execute arbitrary code on the remote host with SYSTEM privileges. For example this vulnerability can be exploited through the WebDAV component of IIS 5.0. A public exploit is available.
    last seen2020-06-01
    modified2020-06-02
    plugin id11413
    published2003-03-18
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11413
    titleMS03-007: Unchecked Buffer in ntdll.dll (815021)

Oval

accepted2011-05-16T04:00:17.953-04:00
classvulnerability
contributors
  • nameTiffany Bergeron
    organizationThe MITRE Corporation
  • nameAnna Min
    organizationBigFix, Inc
  • nameSudhir Gandhe
    organizationTelos
  • nameShane Shaffer
    organizationG2, Inc.
descriptionBuffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
familywindows
idoval:org.mitre.oval:def:109
statusaccepted
submitted2003-10-10T12:00:00.000-04:00
titleWindows ntdll.dll Buffer Overflow
version67

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83237/ms03_007_ntdll_webdav.rb.txt
idPACKETSTORM:83237
last seen2016-12-05
published2009-11-26
reporterH D Moore
sourcehttps://packetstormsecurity.com/files/83237/Microsoft-IIS-5.0-WebDAV-ntdll.dll-Path-Overflow.html
titleMicrosoft IIS 5.0 WebDAV ntdll.dll Path Overflow

Saint

bid7116
descriptionntdll.dll buffer overflow via IIS 5.0 WebDAV
idwin_patch_ntdll,web_server_iis_webdav
osvdb4467
titleiis5_webdav
typeremote

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:5197
last seen2017-11-19
modified2006-10-24
published2006-10-24
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-5197
titleMS Windows WebDAV Remote PoC Exploit